Latest / The Windows Podcast with Fexingo: Microsoft, PC, and Enterprise Windows Conversations / Windows 11 Is Redefining Enterprise Wi-Fi Profile Management
Transcript
- Lucas: Let me start with a number. In the last six months, I've heard from three separate enterprise IT teams who pushed out a routine Windows 11 feature update and suddenly had half their laptops unable to connect to the corporate Wi-Fi. Luna: That's a lot of help desk tickets. What caused it? Lucas: Each case had a slightly different root cause, but the common thread was that Windows 11 is quietly redefining how enterprise Wi-Fi profiles work. And if your network infrastructure hasn't kept pace, the OS will simply refuse to connect. Luna: So this isn't a bug. This is Microsoft deliberately tightening the screws. Lucas: Exactly. And I think most IT admins haven't noticed because the changes are happening inside the Wi-Fi profile itself — the XML blob that tells Windows how to authenticate. The big one is that Windows 11 is deprecating older EAP methods. Luna: EAP being Extensible Authentication Protocol. So which methods are being cut? Lucas: Specifically, support for PEAP with MS-CHAPv2 is being phased out. That's been the default for thousands of enterprises for over a decade. Microsoft wants everyone on eap tls, which uses machine or user certificates. Luna: That's a massive shift. PEAP is practically the default for 802.1X deployments. Lucas: Right. And it's not just the authentication method. Windows 11 now enforces TLS 1.2 as the minimum for eap tls. If your RADIUS server only supports TLS 1.0 or 1.1, your clients will fail to connect. I've seen this catch organizations that are still running Windows Server 2012 R2 as their Network Policy Server. Luna: So the RADIUS server itself needs an update. That's not a quick fix. Lucas: No, because updating the RADIUS server might require a whole OS upgrade, which then might require new hardware. And there's another layer: Windows 11 no longer supports TKIP for encryption on Wi-Fi. It's WPA2-AES or WPA3 only. If your access points are configured to allow TKIP as a fallback, Windows 11 will reject the connection. Luna: Wait, TKIP has been deprecated for years. But I bet some legacy access points still have it enabled for backward compatibility. Lucas: Exactly. And the Windows Wi-Fi client is now honoring the OS policy, not the AP's fallback. So even if the AP offers TKIP, Windows 11 says no. The result is that users see 'Can't connect to this network' with no obvious reason. Luna: This sounds like a perfect storm for enterprises that haven't done a Wi-Fi profile audit in the last two years. Lucas: It is. And the tooling has also changed. In Windows 10, you could manage Wi-Fi profiles via Group Policy. In Windows 11, Microsoft is pushing everyone to use the Wi-Fi settings Configuration Service Provider, or CSP, which is managed through Intune or MDM. Luna: So Group Policy for Wi-Fi is effectively deprecated? Lucas: It still works for now, but Microsoft's documentation says the CSP is the recommended path. And more importantly, the CSP supports the newer authentication methods natively. If you try to push a PEAP profile through Group Policy, it might still work on Windows 11 today, but Microsoft has signaled that future feature updates could break it. Luna: So IT teams need to migrate their Wi-Fi profiles from Group Policy to Intune CSP? That's a whole project. Lucas: It is. And it's not just a matter of copying the XML. The CSP expects a different schema. You also have to ensure that the certificates for eap tls are deployed correctly. A lot of organizations rely on auto-enrollment from Active Directory Certificate Services, but that has its own quirks on Windows 11. Luna: We've covered certificate auto-enrollment before. So this is another place where the certificate infrastructure has to be solid. Lucas: Right. And there's a subtler issue: Windows 11 now validates the server certificate during eap tls more strictly. If the RADIUS server's certificate doesn't have the correct extended key usage or if the root CA isn't trusted, the connection fails. Previously, many enterprises had relaxed validation. Luna: I've heard of companies that use self-signed certificates on their RADIUS servers. That's going to break for sure. Lucas: Absolutely. And the fix isn't just to trust that certificate. You need a proper PKI with a trusted root. So this is really forcing enterprises to mature their certificate management. Luna: It's interesting that Microsoft is doing this through the Wi-Fi profile rather than through a separate security policy. It feels like they're baking these requirements into the connectivity layer itself. Lucas: That's exactly what they're doing. And it's consistent with their broader push toward passwordless and zero trust. If you can't authenticate securely, you don't get on the network. No more band-aids. Luna: Let me ask the practical question. If I'm an IT admin listening to this, what should I do today? Lucas: First, audit your current Wi-Fi profiles. Check what EAP method you're using. If it's peap ms-CHAPv2, start planning a move to eap tls. Second, verify your RADIUS servers support TLS 1.2. Third, check your access points' encryption settings — disable TKIP if it's still enabled. Luna: That's a good start. And I'd add: test with a small pilot group on Windows 11 24H2 if you can. The next feature update is expected later this year, and it might enforce these changes more aggressively. Lucas: Right. And while you're testing, also look at your Intune or MDM configuration. If you haven't moved your Wi-Fi profiles to the CSP, start that migration now. The Group Policy path might work today, but it's not going to be supported forever. Luna: This reminds me of the shift from NTLM to Kerberos in the early 2000s. It took years, but eventually everyone had to move. Lucas: Exactly. And the enterprises that waited until the deadline were the ones that had the biggest outages. The ones that planned ahead had a smooth transition. Luna: So the key message: Windows 11 is changing the rules for Wi-Fi authentication, and IT teams need to act now, not when the update breaks connectivity. Lucas: Exactly. And one more thing: don't forget about guest networks. Even if your corporate SSID is using eap tls, guest networks often use captive portals or PSK. Windows 11 hasn't changed much there, but it's worth confirming that the captive portal detection still works. Luna: Good point. I've seen cases where Windows 11's captive portal detection fails because the portal doesn't redirect properly over HTTPS. Lucas: Right. So test that too. The bottom line is that Wi-Fi profile management on Windows 11 is no longer a set-it-and-forget-it task. It requires active maintenance, and the tools are shifting from on-premises Group Policy to cloud-based MDM. Luna: And that's a big cultural shift for IT teams that are used to managing everything locally. Lucas: It is. But the payoff is a more secure and reliable wireless network. And honestly, the writing has been on the wall for a while. Microsoft has been deprecating legacy authentication methods across the board — for email, for web, and now for Wi-Fi. Luna: It's part of that zero-trust journey. You have to authenticate every device and user before granting network access. Lucas: Exactly. And Windows 11 is the enforcement point. So if you're an enterprise IT admin, now is the time to act. Your laptops are going to start refusing connections, and you want to be ahead of that curve. Luna: I think this is one of those topics that sounds dry upfront but has huge operational impact. A single Wi-Fi profile misconfiguration can bring a whole floor to a standstill. Lucas: Absolutely. And to bring it back to the numbers: I mentioned three IT teams at the start. They each spent weeks troubleshooting because they didn't realize Windows 11 had changed these defaults. So this episode is really about saving you that pain. Luna: Hopefully our listeners can avoid those help desk tickets. Lucas: Right. And you know, while we're on the subject of avoiding pain — I want to say something about how we approach these episodes. Luna: Go ahead. Lucas: We keep this show ad-free by design. No sponsor reads, no affiliate links, no commercials. That's a deliberate choice because we want the information to be clean and direct. Luna: Yeah, and we know that really matters to our listeners. You come here for the specifics, not a sales pitch. Lucas: Exactly. So if you find value in that approach — and if today's Wi-Fi profile breakdown saved you some headaches — the simplest way to support the show is a small donation at buy me a coffee dot com slash fexingo. That's it. No tiers, no perks, just a way to say 'keep this going'. Luna: It helps us keep doing deep dives like this one. And we appreciate it. Lucas: Okay, back to the tech. I want to mention one more thing that caught my eye: Windows 11 now supports WPA3-Enterprise 192-bit mode. Luna: That's the government-grade security mode. Also known as WPA3-Enterprise with CNSA Suite B. Lucas: Right. And it requires GCMP-256 encryption. That's a big jump, but it also means your RADIUS server and access points need to support it. So if you're in a regulated industry, this might be your next target after the eap tls migration. Luna: But most enterprises aren't there yet. They're still struggling with the basics. Lucas: Exactly. So the priority is getting off PEAP, enabling TLS 1.2, and moving profiles to Intune. Once that's stable, you can think about WPA3. Luna: Sound advice. And to close, I think the big takeaway is: Wi-Fi profile management on Windows 11 is now a first-class security concern, not just a networking detail. Lucas: Well said. And it's one of those areas where proactive work saves you from reactive firefighting. So check your profiles, check your certificates, and check your RADIUS servers. Do it now, before the next feature update does it for you. Luna: Thanks for listening, everyone. We'll be back with another deep dive soon.